Apache AirflowGHSA-mjqh-v5f2-g2mw
Apache Airflow information exposure vulnerability
High6.5CVE-2023-40712 · Published Sep 12, 2023 · updated Nov 22, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.7.1 | 2.7.1 |
Details and references
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-airflow-2023-40712, CVE-2023-40712, PYSEC-2023-171
- nvd.nist.gov/vuln/detail/CVE-2023-40712
- github.com/apache/airflow/pull/33512
- github.com/apache/airflow/pull/33516
- github.com/apache/airflow/commit/4390524a41fdfd2d57f1d2dc98ad7b4009c8399e
- github.com/apache/airflow/commit/d9814eb3a2fc1dbbb885a0a2c1b7a23ce1cfa148
- github.com/apache/airflow
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-171.yaml
- lists.apache.org/thread/jw1yv4lt6hpowqbb0x4o3tdp0jhx2bts
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 122023 | Apache Airflow Incorrect Authorization vulnerability CVE-2023-40611Medium4.3fixed in 2.7.1 | Medium4.3 | 2.7.1 |
| Aug 232023 | Apache Airflow missing Certificate Validation CVE-2023-39441Medium5.9fixed in 2.7.0 | Medium5.9 | 2.7.0 |
| Aug 232023 | Apache Airflow Session Fixation vulnerability CVE-2023-40273High8.0fixed in 2.7.0rc2 | High8.0 | 2.7.0rc2 |
| Aug 232023 | Apache Airflow denial of service vulnerability CVE-2023-37379High8.1fixed in 2.7.0b1 | High8.1 | 2.7.0b1 |
| Aug 112023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. CVE-2023-39553High7.5fixed in 2.4.3 | High7.5 | 2.4.3 |
| Oct 142023 | Apache Airflow vulnerable to sensitive information exposure CVE-2023-42663Medium6.5fixed in 2.7.2 | Medium6.5 | 2.7.2 |